Educause Security Discussion mailing list archives

Re: Student Passwords


From: Joel Rosenblatt <joel () COLUMBIA EDU>
Date: Wed, 7 Dec 2011 06:24:30 -0500

Hi,

Here is our password page

<http://cuit.columbia.edu/cuit/it-security-practices/using-strong-passwords>

min 8, max 64, include at least 1 number or special character, punctuation or space

We encourage the use of a pass phrase

Joel

--On Tuesday, December 06, 2011 9:51 PM -0700 "SCHALIP, MICHAEL" <mschalip () CNM EDU> wrote:

We'd really like to refresh this discussion as well.....15 characters - no complexity - change every 128 days - last 5 
passwords are retained....

What are others doing?  Is everyone else still at 6-8 characters?

Thanks....



________________________________________
From: The EDUCAUSE Security Constituent Group Listserv [SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Daniel Bennett 
[dbennett () PCT EDU]
Sent: Tuesday, December 06, 2011 9:40 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] Student Passwords

This has gone around a few times in the past but I am looking for fresh results.

What is your stance on student passwords?  Do you make them change their password every X number of days?  Complexity 
rules? Etc.

Thanks.
--
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.
--
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.




Joel Rosenblatt, Manager Network & Computer Security
Columbia Information Security Office (CISO)
Columbia University, 612 W 115th Street, NY, NY 10025 / 212 854 3033
http://www.columbia.edu/~joel
Public PGP key
http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x90BD740BCC7326C3


Current thread: